Zombie Accounts: What SOC 2 and ISO 27001 Auditors Actually Check When They Sample Your Offboarding

SOC 2 and ISO 27001 auditors sample past offboardings and ask for proof. See what they check, what most companies can't produce, and how to fix it.

200+ companies already trust deeploi

Direct Answer

SOC 2 and ISO 27001 auditors don't review every offboarding, they sample a handful of departures from the past 12 months and ask for a timestamped log proving exactly when access was revoked, by whom, and across which systems. Most companies can prove this for email and the identity provider, but not for SaaS tools outside SSO or API tokens, which is the most common finding auditors write up. deeploi generates this evidence automatically at the moment access is revoked, so the audit trail already exists when the sample request comes in.

Key Takeaways

  • Auditors sample, they don't audit everything: SOC 2 Type II and ISO 27001 auditors typically pull five or so former employees from the past year and ask for proof of full revocation, not a policy document describing what should happen.
  • "Zombie accounts" are the most common finding: logins that stay active long after someone leaves, usually because they live in a tool outside the identity provider and nobody checked.
  • The evidence window is narrower than most companies assume: frameworks generally expect revocation within 24 hours, and auditors check the gap between the exit date and the revocation timestamp, not just whether it eventually happened.
  • A policy is not evidence: auditors want a timestamped log naming what was revoked, when, and by whom, for the specific people they sampled, not a general offboarding procedure.
  • deeploi generates the audit trail as a byproduct of offboarding itself: every revocation is logged automatically, so producing evidence for a sample doesn't require reconstructing anything after the fact.

An auditor reviewing a company's SOC 2 Type II report doesn't ask to see the offboarding policy. They pick five people who left in the past year and ask for proof: when was each account disabled, by whom, and across which systems. One company can answer for email. Fewer can answer for the CRM, the code repository, or the API key someone generated eighteen months ago. This gap has a name in security circles, zombie accounts, and it's the single most common finding in access-control audits. deeploi, the all-in-one IT management platform for growing companies, builds the evidence trail into the offboarding process itself, so producing it for a sample isn't a scramble. This article walks through what auditors actually sample, what they expect to see, and why most companies can prove less than they think.

Offboarding Audit

SOC 2 and ISO 27001, in Plain Terms

SOC 2 is a US-originated auditing standard that certifies how well a company protects customer data, covering principles like security and availability. It's frequently required by American enterprise customers before they'll sign a contract, which is why it comes up so often for scale-ups selling into the US. ISO 27001 is an international standard for an information security management system, and it's the more common baseline expectation in Europe, including much of the DACH market. Both require an independent auditor to test whether a company's security controls, offboarding included, actually hold up in practice, not just whether they look reasonable on paper.

Why Auditors Sample Instead of Reviewing Everything

Neither SOC 2 Type II nor ISO 27001 audits check every employee departure. Reviewing a full year of offboardings for every client would make audits impossibly slow, so auditors use sampling instead: they pull a handful of departures, usually around five, from the population of people who left in the audit period, and treat that sample as representative of the whole process.

This changes what actually matters. A company doesn't need to prove its offboarding process is theoretically sound. It needs to produce specific, timestamped evidence for the specific people the auditor happened to sample. If the process worked for four of the five but the fifth has a gap, that gap becomes a documented exception in the audit report, regardless of how solid the other four look.

For each sampled departure, auditors typically request:

  • A timestamped log showing exactly when the account was disabled
  • Confirmation that software licenses tied to that person were removed
  • Evidence that company hardware was recovered or accounted for
  • A named individual responsible for carrying out the revocation

Producing this after the fact, months after someone left, is where most companies run into trouble. The information technically exists somewhere, in a ticketing system, an email thread, someone's memory, but assembling it into a clean, timestamped answer for one specific person is slow and often incomplete.

What Auditors Actually Ask For

The table below reflects what a typical SOC 2 or ISO 27001 sample request looks like, and where companies most often come up short.

Evidence requested Why it matters Where companies typically fall short
Timestamped revocation log Proves access was cut on a specific date, not just eventually Exists for the identity provider, rarely for standalone SaaS tools
Named responsible party Shows the process has real ownership, not an assumption someone handled it Often missing when offboarding is handled ad hoc across HR and IT
License removal confirmation Confirms no ongoing access through a paid seat Frequently overlooked for tools outside the core SSO setup
API key and token status Proves machine credentials were revoked, not just the human login The single most common gap; disabling a user doesn't revoke tokens
Hardware disposition Confirms company devices were recovered, wiped, or otherwise accounted for Usually fine for on-site staff, weaker for remote departures

Notice what's absent from this list: a policy document. Auditors already assume most companies have one. What they're testing is whether the policy was actually followed for the specific people they picked, which is a very different bar.

{{cta}}

SOC 2 vs. ISO 27001: What Each Framework Expects

The two frameworks overlap heavily on offboarding, but they're not identical in how they sample and what they weigh most heavily.

Aspect SOC 2 Type II ISO 27001
Sampling approach Samples terminations across the audit period, typically a rolling 6 to 12 months Sampled during annual surveillance audits, based on the certified ISMS scope
What's emphasized Operating effectiveness over time, evidence that controls consistently worked Documented procedure (Annex A control A.5.11 and related) plus evidence it was followed
Typical expected timeframe Commonly within 24 hours or one business day of the termination Defined by the organization's own policy, then tested for adherence
Consequence of a gap Documented exception in the report, can affect customer trust in the audit Nonconformity, may require a corrective action plan before certification stands

The practical takeaway is the same either way: both frameworks expect a defined timeframe and specific, per-person evidence, not a general assurance that offboarding "works."

Zombie Accounts and Orphan Secrets: Why the Same Gaps Keep Showing Up

Two terms come up repeatedly once you're looking at this from an audit perspective rather than an IT perspective.

A zombie account is a login that stays active long after the person who used it has left, usually in a tool that sits outside the identity provider and therefore doesn't get touched when the main account is disabled. An orphan secret is the machine-credential version of the same problem: an API key, personal access token, or OAuth grant that keeps authenticating independently of any human login, often created by someone who has since left and forgotten it existed.

Neither shows up in a routine check. They surface only when someone specifically goes looking, which in practice usually means either a security incident or an audit sample. That's exactly why they're the finding auditors write up most often: not because companies are careless, but because these gaps are invisible by default.

Automating the Evidence, Not Just the Offboarding

Manually running an offboarding checklist can revoke access correctly and still leave you without usable audit evidence, because the proof of what happened often lives across several tools, tickets, and people's memory instead of one record.

deeploi ties access revocation to a single offboarding event and logs every step automatically: what was revoked, when, and by whom. When an audit sample request comes in, the evidence already exists in the same form the auditor expects, rather than needing to be reconstructed from scattered sources under time pressure. Companies using deeploi report up to 98% less IT workload on tasks like this, largely because the audit trail is a byproduct of the process rather than a separate project.

Conclusion

An offboarding process can work perfectly and still fail an audit, if nobody can produce evidence for the specific people sampled. The gap is rarely dishonesty, it's that proof lives in scattered tools instead of one record. deeploi builds that record automatically, so the evidence is ready before the sample request ever arrives.

Your IT in the best hands. See how deeploi works

FAQ

What is a zombie account in an audit context?

A zombie account is a login that remains active long after the person who used it has left the company, usually because it lives in a tool outside the identity provider and wasn't checked during offboarding.

How many former employees do SOC 2 auditors typically sample?

There's no fixed number in the standard itself, but auditors commonly pull around five departures from the audit period as a representative sample, rather than reviewing every termination.

What evidence do auditors expect for access revocation?

A timestamped log showing what was revoked and when, confirmation that licenses were removed, a named person responsible, and evidence covering both human accounts and machine credentials like API keys.

What happens if a company can't produce revocation evidence during an audit?

It typically becomes a documented exception in a SOC 2 report or a nonconformity under ISO 27001, which can require a corrective action plan and may affect certification timelines.

Does ISO 27001 require the same evidence as SOC 2?

The two overlap significantly, both expect timely, documented revocation, but ISO 27001 ties evidence more directly to a documented procedure under the certified management system, while SOC 2 focuses on operating effectiveness across the audit period.

Founded
Customer Size
Headquarters
Industry
KEY RESULTS
CUSTOMER STORIES
This field is required
This field is required
This field is required
Choose
This field is required
This field is required
Thank you for your interest!

We’ll get back to you shortly.

Oops! Something went wrong while submitting the form.

Get the free offboarding checklist

Built with IT experts and tested by HR teams, this checklist turns every exit into a clean handover that protects the company and respects the person leaving.
Download the professional onboarding checklist for free

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Get the checklist